US12034765B1ActiveUtility
Securing network access with legacy computers
Est. expiryJul 24, 2043(~17 yrs left)· nominal 20-yr term from priority
Inventors:Mordecai Barkan
H04L 63/0281H04L 63/0428H04L 63/1475H04L 63/145
93
PatentIndex Score
3
Cited by
12
References
7
Claims
Abstract
Off-the-shelf computing systems, even in the presence of malware infecting those computing systems, are used to access securely other network computing systems—Secured sites. The use may take shape in various ways and the potential use of two, three, or more computing systems is described. The use in a malware-infected environment is advantageous and exposes hacking attempts in real-time.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1. A method for secure communication with a network node hosting a site by utilizing multiple computing devices, comprising the steps of:
configuring the site of the network node hosting the site to enable a user secured communication session by utilizing the multiple computing devices;
initiating the multiple computing devices and managing communication sessions between the user and the network node hosting the site;
utilizing multiple computing devices by the user to establish secure communication channels with the network node hosting the site;
splitting a session initiated by the user with the site of the network node hosting a site into multiple distinct sessions, where each session is carried out by one of the multiple computing devices used by the user to support a single session with the site of the network node hosting a site;
ensuring secure transmission of messages between each of the user's multiple computing devices and the network node hosting the site, maintaining data confidentiality and integrity during transmission by segregating and avoiding eavesdropping of the user communication of a combined session; and
implementing a security mechanism that, in the event of malware infecting a computing device of the multiple computing devices utilized by the user, restricts the malware's access to only a portion of the user's session on the infected computing device, thereby safeguarding the integrity of the overall communication between the user and the site of the network node hosting a site across the multiple computing devices.
2. The method according to claim 1 , further comprises the steps:
establishing communication between the multiple computing devices and the network node hosting a site, wherein said communication involves the utilization of a masking technique;
transmitting at least one mask from the network node hosting the site to a first computing device over the network;
integrating sensitive information with the transmitted mask to the first computing device by the user by means of a second computing device;
transmitting the integrated sensitive information with the mask from the second computing device to the network node hosting the site, using the second computing device, thereby preventing exposure of the sensitive information to malware that may infect the second computing device while preventing access by the first computing device to the integrated sensitive information; and
extracting the sensitive information at the network node hosting the site by removing the mask sent to the first computing device from the integrated sensitive information received from the second computing device.
3. The method according to claim 1 further comprises:
validating the operation at the network node hosting the site configured to carry out such operation by:
evaluating messages received from a first computing device, wherein the mask is integrated with seeded information;
evaluating messages received from the second computing system, wherein sensitive information is integrated with the mask; and
retrieving the sensitive information on the site and storing the seeded message for detection of hacking attempts.
4. The method according to claim 1 , wherein the site of the network node hosting the site is configured to detect hacking attempts by:
identifying messages that include messages received from the first computing system, where the mask is integrated with seeded information; and
identifying messages that include messages received from the second computing system, where sensitive information is integrated with the mask.
5. The method according to claim 1 , further comprising:
using more than two computing systems simultaneously and out-of-band communication; and
hardening and further securing user communication with the site of the network node hosting the site by splitting session portions between the multiple computing devices.
6. The method according to claim 1 , wherein:
at least two matched users communicate over the network with the site of the network node hosting the site;
the site of the network node hosting the site serves as a proxy; and
pairing, account opening, accessibility functions, and sharing of information are applied securely between the users and the site of the network node hosting the site.
7. A site hosted by a network node, to enable secure communication with the site by a user utilizing multiple computing devices, configured:
to initiate and manage a main session by the user;
allowing for multiple computing devices to access the site and be used by the user;
each of said multiple computing devices configured to establish secure communication channels with the network node hosting the site;
splitting the main session initiated by the user into multiple distinct secondary sessions, with each of the secondary sessions handled by one of the multiple computing devices utilized by the user to support a single session with the site of the network node hosting a site;
securing transmission of messages between each of the multiple computing devices and the site hosted by the network node, ensuring data confidentiality and integrity during transmission by segregating and avoiding eavesdropping of the user communication of a combined session; and
in the event of malware infecting one of the multiple computing devices utilized by the user, the malware access is restricted to only the secondary session carried by one of the multiple computing devices utilized by the user, thereby safeguarding the integrity of the overall communication between the user and the site hosted by the network node hosting a site across the multiple computing devices.Join the waitlist — get patent alerts
Track US12034765B1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.